Tenable wins FedRAMP High and IL5 auth for cloud exposure platform
Tenable Holdings has announced that its Tenable One Cloud Exposure product has received FedRAMP High and Impact Level 5 (IL5) authorisation from the US government. The certification, processed through UberEther's AIM Advantage platform, is one of the most demanding security accreditations available to commercial cloud vendors operating in the federal space and significantly broadens the addressable market for the Columbia, Maryland-based company.
The milestone builds on existing FedRAMP Moderate authorisations that Tenable already holds for both Tenable One Cloud Exposure and the broader Tenable One Exposure Management Platform. The new authorisation extends the company's reach into highly sensitive federal environments, including those operated by the Department of War and US intelligence agencies, and unlocks mission-critical use cases such as classified workloads and tactical edge deployments.
What the authorisation covers
Tenable One Cloud Exposure is positioned as a Cloud Native Application Protection Platform (CNAPP) that consolidates cloud infrastructure visibility, identity risk management and continuous compliance monitoring into a single service. The release says the platform applies AI-powered contextual analysis to identify misconfigured workloads and close exposure gaps across the cloud lifecycle. Tenable says its identity analytics layer is designed to enforce zero-trust principles in line with Department of War CIO mandates.
Bob Huber, Chief Security Officer and President of Tenable Public Sector, said the authorisation "validates our ability to protect the most sensitive cloud workloads" and positions the platform as a tool for federal agencies seeking to adopt AI capabilities without increasing their risk posture. Tenable did not disclose the number of federal contracts expected to be unlocked by the certification, nor any revenue guidance associated with the expanded clearance level.
Market and competitive context
The federal cloud security market is a well-funded and fiercely contested segment, with established players including Palo Alto Networks (Prisma Cloud), CrowdStrike (Falcon Cloud Security), Wiz and Microsoft Defender for Cloud all competing for agency budgets. FedRAMP High and IL5 authorisation is a meaningful differentiator: it narrows the competitive field considerably, because achieving that accreditation requires significant investment in audit, operational controls and third-party assessment, and not all commercial vendors have committed the resources to pursue it.
Federal agencies are under sustained pressure to modernise ageing IT estates and consolidate fragmented security tooling. The Cybersecurity and Infrastructure Security Agency (CISA) has been actively pushing departments towards zero-trust architecture frameworks through its binding operational directives, while the Office of Management and Budget's M-22-09 memorandum set a 2024 deadline for agencies to meet specific zero-trust maturity targets. These mandates have materially increased demand for accredited, consolidated CNAPP offerings capable of spanning multi-cloud and hybrid environments.
Regulatory read-across
IL5 sits one tier below IL6, which is reserved for classified national-security systems handled under different procurement frameworks. Securing IL5, however, positions Tenable to compete for contracts covering controlled unclassified information and some national-security workloads, a category that carries higher average contract values than the IL2/Moderate tier where most commercial SaaS vendors compete. The authorisation also aligns with the broader NIS2 and DORA push in Europe, where cloud-security consolidation and provable compliance posture are becoming baseline procurement requirements for regulated-sector buyers, providing Tenable with a compliance narrative that may transfer to non-US markets.
Tenable serves more than 40,000 customers globally across commercial and government sectors. The company has not disclosed when it expects to begin onboarding classified federal customers under the new authorisation, but the announcement signals a clear strategic intent to deepen its public-sector revenue base as federal cloud modernisation budgets continue to grow.